Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63310

Опубликовано: 22 авг. 2026
Источник: redhat
CVSS3: 7.1

Описание

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

Отчет

Red Hat has rated this issue as having an Impact of Important. This flaw is only exploitable when application code calls NLTK's downloader module (e.g. nltk.download()) to fetch corpora or model packages from the network at runtime, and an attacker is able to intercept or redirect that traffic via a man-in-the-middle position or DNS poisoning. Red Hat products that vendor nltk but do not invoke the downloader at runtime -- for example, images that ship pre-bundled NLTK data baked in at build time -- are not affected by this flaw regardless of the packaged nltk version.

Меры по смягчению последствий

Upgrade the nltk package to version 3.9.3 or later, which adds post-download integrity verification before extraction. Pin this minimum version in requirements files, lockfiles, and container image builds for all affected components. Where an immediate upgrade is not possible: avoid invoking NLTK's automatic downloader over untrusted or unauthenticated networks. Pre-download and independently verify the required NLTK data packages from a trusted source, host them in an internal, integrity-checked artifact repository, and point NLTK_DATA at that vetted local store so the runtime process never fetches data over the wire. Enforcing TLS with certificate validation and using trusted, DNSSEC-validated resolvers for the download endpoint reduces exposure to MITM/DNS-poisoning attacks but does not substitute for upgrading, since the underlying missing-integrity-check flaw remains present.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Under investigation
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Not affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-494
https://bugzilla.redhat.com/show_bug.cgi?id=2521337nltk: NLTK before 3.9.3 Missing Post-Download Integrity Verification

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
nvd
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

CVSS3: 7.1
debian
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading pac ...

CVSS3: 7.1
github
13 дней назад

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

7.1 High

CVSS3